HIGHVulnerability
Verified
Global
CISA KEV: Arista VeloCloud Orchestrator — Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
Analysis
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-22. Remediation due: 2026-09-25.